Google Workspace extended and enhanced its built-in security control and artificial intelligence (AI)-powered defense capabilities to boost users’ zero-trust maturity and data protection.

Google Workspace, formerly known as G Suite, offers a range of software applications and services for communication, collaboration and document storage, including Google Drive, Gmail, Google Docs, Meet and admin console.

For data security, the suite has been providing built-in controls like data loss prevention (DLP) and context-aware access (CAA), which also help organizations accelerate their zero-trust adoption, Google claims.

To enhance the granular controls over data use and access, the tech giant is now previewing a feature that is designed to allow administrators to use AI models to automatically classify and label new and existing files in Google Drive.

“Google has also been a leader in AI, in addition to zero trust, and so what we're doing is we're bringing the two together and adding an ability to improve how you classify with using AI capabilities within Drive,” Jeanette Manfra, senior director of Global Risk and Compliance for Google Cloud, said during a press conference for the announcements.

The new feature “automatically and continuously classifies and labels sensitive data and then applies appropriate risk-based controls,” she added. These controls such as DLP and CAA can be applied based on the customer's risk tolerance and their security policies.

Additionally, “we're helping organizations train their own AI models on what data is most sensitive to their organization and to what degree,” Manfra said. “Protecting sensitive data is one of the most challenging things that organizations have to face.”

And one of the pain points in this data protection challenge for many organizations is to label the data manually, echoed Andy Wen, director of product management for Google Workspace. “If you just simply put a number of documents into a folder, our DLP AI does a great job of identifying those documents across the enterprise.”

Google advances DLP controls for Drive and Gmail

The DLP capabilities are already available in Google Chat, Drive and Chrome and now the company has extended them to Gmail, which will be in preview later this year.

“This can particularly help organizations that are struggling with preserving sensitive data when it shows up, especially in unexpected places,” Manfra said, adding this feature allows organizations to raise the bar on their security policies.

Google also introduced context-aware DLP controls in Drive, which enables administrators to set criteria, like device location or security status, to control how sensitive content is shared.

AI-powered defenses for identity-based attacks

The introduction of new capabilities comes at a time when security attacks are on the rise, up 38% in the last year alone, with each data breach costing organizations an average of $4.35 million. And social engineering attacks like phishing remain a prevalent entry point for data breaches.

To help detect and respond to these identity-based attacks, Google uses its own AI capabilities to automatically secure additional sensitive actions in Gmail, such as email filtering or forwarding.

“For decades, Google has been using AI in many different ways to combat phishing by blocking over 99.9% of spam, phishing and malware,” Wen said. “Now we're extending this capability to your account behavior.”

For example, when a hacker breaks into a user’s Gmail account, typically the first thing they tend to do is search for cryptocurrency accounts and wallets, then they will set up email filtering and forwarding to get a copy of these emails. Google will use AI to deploy two-step or two-factor verifications to determine the identity of the user when detecting unusual behaviors.

“This is often the first point where we can alert users that their accounts have been hacked and help them get their accounts back,” he said.

Additional capabilities Google is rolling out for preventing Workspace account takeovers include mandating two-step verifications for select enterprise administrators, starting with its largest enterprise customers. A second is allowing Workspace logs to be exported to its cloud-native security operations suite Chronicle for AI-powered investigations. A third is requiring multi-party approval for sensitive administrator actions.